发明授权
- 专利标题: Processing anomaly data to identify network security threats by use of rarity analysis
-
申请号: US17845383申请日: 2022-06-21
-
公开(公告)号: US11824646B1公开(公告)日: 2023-11-21
- 发明人: Sudhakar Muddu , Christos Tryfonas
- 申请人: Splunk Inc.
- 申请人地址: US CA San Francisco
- 专利权人: SPLUNK INC.
- 当前专利权人: SPLUNK INC.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Perkins Coie LLP
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; G06N20/00 ; G06F16/25 ; G06F16/28 ; G06F16/44 ; G06F16/901 ; G06F16/2457 ; H04L43/00 ; G06F40/134 ; G06N20/20 ; G06V10/22 ; G06F3/0482 ; G06F3/0484 ; G06F3/04847 ; H04L41/0893 ; H04L43/062 ; H04L43/045 ; H04L43/08 ; G06F3/04842 ; G06N5/04 ; H04L41/14 ; H04L41/22 ; G06N5/022 ; G06N7/01
摘要:
A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
信息查询